<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
 xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
 xmlns:admin="http://webns.net/mvcb/"
 xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
 xmlns:content="http://purl.org/rss/1.0/modules/content/"
 xmlns:wfw="http://wellformedweb.org/CommentAPI/">
<channel>
<title>Daniel Nashed&#8217;s Blog</title>
<description>Domino on Linux/Unix, Troubleshooting, Best Practices, Tips and more ...</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/</link>
<language>en-us</language>
<lastBuildDate>Sun, 19 Jul 2026 21:23:08 +0200</lastBuildDate>
<item>
<title>Use an USB device like a camera from a remote machine</title>
<pubDate>Sun, 19 Jul 2026 21:23:08 +0200</pubDate>
<description>
<![CDATA[ 
How cool is that. I wanted to use my new camera should work on multiple devices without plugging it into a different machine all the time. ChatGPT came up with this project https://www.virtualhere. ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm</link>
<category>USB</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">How cool is that. I wanted to use my new camera should work on multiple devices without plugging it into a different machine all the time.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> ChatGPT came up with this project </span><a href=https://www.virtualhere.com/><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://www.virtualhere.com/</u></span></a><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> From what I read it is free for one USB device.<br /> It works on multiple platforms. In my case I plug the camera into my M4 and share it with other machines like my Thinkpad.<br /> <br /> A camera needs quite some bandwidth and low latency. I my first tests it worked pretty good.</span><span style=" font-size:12pt"> </span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><br /> -- Daniel</span><span style=" font-size:12pt"> <br /> <br /> </span><img  alt="Image:Use an USB device like a camera from a remote machine" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span><img  alt="Image:Use an USB device like a camera from a remote machine" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm/content/M3?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span><img  alt="Image:Use an USB device like a camera from a remote machine" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm/content/M4?OpenElement" /><span style=" font-size:12pt"><br /> <br /> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/use-an-usb-device-like-a-camera-from-a-remote-machine.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/use-an-usb-device-like-a-camera-from-a-remote-machine.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Notes/Domino 14.5.1 FP1 released - Container Image is updated</title>
<pubDate>Thu, 16 Jul 2026 22:43:55 +0200</pubDate>
<description>
<![CDATA[ 
HCL Notes &amp; Domino is available. I have updated the container image with 14.5.1 FP1 and updated all lab and production Linux servers. For Windows I am going to wait for the autoupdate reposito ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/notesdomino-14.5.1fp1-released-container-image-is-updated.htm</link>
<category>Domino</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/notesdomino-14.5.1fp1-released-container-image-is-updated.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/notesdomino-14.5.1fp1-released-container-image-is-updated.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> HCL Notes &amp; Domino is available. <br /> I have updated the container image with 14.5.1 FP1 and updated all lab and production Linux servers. <br /> <br /> For Windows I am going to wait for the autoupdate repository. </span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><strong>Notes/Domino 14.5.1 Fix Pack 1 Release Notice</strong></span> <br /><a href="https://support.hcl-software.com/csm?id=kb_article&amp;sysparm_article=KB0132257"><span style=" font-size:10pt;color:blue;font-family:sans-serif">https://support.hcl-software.com/csm?id=kb_article&amp;sysparm_article=KB0132257</span></a> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><strong>What's New in 14.5.1 Fixpack 1?</strong></span> <br /><a href="https://help.hcl-software.com/domino/14.5.1/admin/whats_new_in_1451FP1.html"><span style=" font-size:10pt;color:blue;font-family:sans-serif">https://help.hcl-software.com/domino/14.5.1/admin/whats_new_in_1451FP1.html</span></a> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><strong>HCL Notes/Domino 14.5.1 FP1 Fix List </strong></span> <br /><a href="https://ds_infolib.hcltechsw.com/ldd/fixlist.nsf/Public?OpenView&amp;Start=1&amp;Expand=1#1"><span style=" font-size:10pt;color:blue;font-family:sans-serif">https://ds_infolib.hcltechsw.com/ldd/fixlist.nsf/Public?OpenView&amp;Start=1&amp;Expand=1#1</span></a> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><br /> Happy updating! <br /> <br /> <br /> </span><img  alt="Image:Notes/Domino 14.5.1 FP1 released - Container Image is updated" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/notesdomino-14.5.1fp1-released-container-image-is-updated.htm/content/M2?OpenElement" /><span style=" font-size:10pt;font-family:sans-serif"><br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/notesdomino-14.5.1fp1-released-container-image-is-updated.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/notesdomino-14.5.1fp1-released-container-image-is-updated.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>How to Build the Domino container with a Hotfix.</title>
<pubDate>Tue, 14 Jul 2026 13:25:13 +0200</pubDate>
<description>
<![CDATA[ 
Interim Fixes are technically distributed as a Hotfix and have a HF number per platform. Those files are available to all customers on maintenance. Hotfixes in contrast are technically the same but ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/how-to-build-the-domino-container-with-a-hotfix..htm</link>
<category>Domino container</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/how-to-build-the-domino-container-with-a-hotfix..htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/how-to-build-the-domino-container-with-a-hotfix..htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> Interim Fixes are technically distributed as a Hotfix and have a HF number per platform.<br /> Those files are available to all customers on maintenance.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Hotfixes in contrast are technically the same but they are distributed by customer for critical issues.<br /> <br /> The HCL Domino container community project can install Hotfixes during the container build.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> You have to download the file to your software directory or download repository and run the build command specifying the file.<br /> There are currently no checksum checks like for other software, because HCL does not provide those checksums to customers. <br /> Once available it would be easy to add.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Here is an example command-line how to build the image.<br /> <br /> The version information is still important to label the image correctly.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> But the hotfix file overrides getting it from software.txt.</span><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> ./build.sh domino 14.5.1 HF51 -hf_download=1451HF51-linux64.tar latest</span></tt><span style=" font-size:12pt"> </span> <br /> <br /> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">the versions trigger the Domino software to be downloaded and for labeling</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">&nbsp;</span><tt><span style=" font-size:10pt">-hf_download=</span></tt><span style=" font-size:10pt;font-family:sans-serif"> overrides software.txt</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">latest labels the resulting image as latest. You can also use -tag=xyz to specify your own tag</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> An alternate way would be to add the file to software.txt. But then you also need to calculate the SHA256 hash and add it.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This override might be the easier path.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> -- Daniel</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/how-to-build-the-domino-container-with-a-hotfix..htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/how-to-build-the-domino-container-with-a-hotfix..htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Introducing Domino Operations &amp; Change Management with Grafana Integration</title>
<pubDate>Fri, 10 Jul 2026 00:54:57 +0200</pubDate>
<description>
<![CDATA[ 
I am working on a new project for change management and incidents in combination with Grafana alerting to create incidents and close them automatically. The integration is implemented using the webh ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm</link>
<category>Grafana</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> I am working on a new project for change management and incidents in combination with Grafana alerting to create incidents and close them automatically.<br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">The integration is implemented using the webhook interface on Grafana alerting side.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The webhook posts to a Lotus Script agent which creates and closes incidents.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This brings together multiple components:</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <strong><br /> 1. Prometheus Domino Statistics --&gt; 2. Grafana Alerting --&gt; 3. WebHook Agent --&gt; 4. Domino Operations &amp; Change Management database (ocm.nsf).</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Here is an example for a disk space rule in action.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> It plays hand in hand with my Domino Fleet Manager application (DFM / dfm.nsf) which provides SD scrape targets for dynamic metric endpoint scraping.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I am not sure if this is going to be a product or an open source project.</span><span style=" font-size:12pt"><br /> <br /> </span><img  alt="Image:Introducing Domino Operations &amp; Change Management with Grafana Integration" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span><img  alt="Image:Introducing Domino Operations &amp; Change Management with Grafana Integration" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm/content/M3?OpenElement" /><span style=" font-size:12pt"><br /> <br /> <br /> <br /> </span><img  alt="Image:Introducing Domino Operations &amp; Change Management with Grafana Integration" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm/content/M4?OpenElement" /><span style=" font-size:12pt"><br /> <br /> <br /> <br /> <br /> <br /> </span><img  alt="Image:Introducing Domino Operations &amp; Change Management with Grafana Integration" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm/content/M5?OpenElement" /><span style=" font-size:10pt;font-family:sans-serif"> &nbsp;</span><img  alt="Image:Introducing Domino Operations &amp; Change Management with Grafana Integration" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm/content/M6?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/introducing-domino-operations-change-management-with-grafana-integration.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domino-operations-change-management-with-grafana-integration.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Introducing DomProbe – The Missing Piece for Prometheus NRPC Monitoring</title>
<pubDate>Sun, 5 Jul 2026 14:52:20 +0200</pubDate>
<description>
<![CDATA[ 
The Prometheus ecosystem already provides excellent monitoring components. The standard Blackbox Exporter is perfect for probing HTTP, HTTPS, TCP, ICMP and many other network protocols, while export ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domprobe-–-the-missing-piece-for-prometheus-nrpc-monitoring.htm</link>
<category>Domino</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domprobe-–-the-missing-piece-for-prometheus-nrpc-monitoring.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domprobe-–-the-missing-piece-for-prometheus-nrpc-monitoring.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The Prometheus ecosystem already provides excellent monitoring components.<br /> The standard Blackbox Exporter is perfect for probing HTTP, HTTPS, TCP, ICMP and many other network protocols, while exporters such as node_exporter and DomProm provide detailed operating system and Domino server metrics.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> But there has always been one missing piece: <strong>Native NRPC monitoring for HCL Domino.</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> That's exactly why I created <strong>DomProbe</strong>.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Why NRPC Monitoring Matters</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Many critical Domino functions depend on NRPC: Notes client connectivity, replication, clustering, administration, mail routing, and server-to-server communication.<br /> A Domino server may still answer HTTPS requests while NRPC is no longer functioning correctly. Likewise, a simple TCP connection to port 1352 only tells you that something is listening—it does <strong>not</strong> confirm that Domino is actually able to process NRPC requests.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> DomProbe performs a real NRPC transaction using the native Domino C API. It connects to the target server, measures request and response latency, reports the Domino server state, and can optionally verify that a specific database can be opened.<br /> This provides a much more meaningful availability check than simply testing whether port 1352 is open.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> A Natural Extension to the Prometheus Ecosystem</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> DomProbe follows the same architecture as the Prometheus Blackbox Exporter.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Prometheus sends an HTTP request to DomProbe, which performs the NRPC probe and returns the results in standard Prometheus metrics format.<br /> Existing Prometheus and Grafana dashboards, alert rules, and scrape configurations work exactly as expected—the only difference is that the probe itself understands Domino.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Typical metrics include:</span><span style=" font-size:12pt"> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">NRPC availability</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Domino server state (Available, Restricted, Busy, Not Reachable)</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Client-to-server latency</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Server-to-client latency</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Total probe duration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Optional database open verification and timing</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Combined with DomProm and node_exporter, this finally completes the monitoring stack for Domino environments.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Monitor Your Entire Domino Infrastructure</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Although DomProbe runs as a native Domino server task on Linux, it is <strong>not limited to probing the local server</strong>.<br /> A single DomProbe instance can probe any Domino server reachable via NRPC.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> For example, you might deploy one DomProbe instance in each data center:</span><span style=" font-size:12pt"> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">A Domino server in <strong>Data Center A</strong> probes all production servers in its own site as well as selected servers in <strong>Data Center B</strong>.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Another Domino server in <strong>Data Center B</strong> performs the same checks in the opposite direction.</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> This verifies much more than whether the target servers are running. It also confirms that <strong>NRPC communication between Domino servers is actually working</strong>.<br /> Routing problems, firewall issues, VPN failures, or replication connectivity problems become immediately visible from the perspective of another Domino server.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Since Prometheus simply calls the /probe endpoint with different target parameters, a single DomProbe instance can monitor dozens or even hundreds of Domino servers without requiring additional software on every monitored system.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Lightweight by Design</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> DomProbe intentionally focuses on <strong>availability monitoring</strong>.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> It does not try to replace detailed monitoring solutions such as DomProm or node_exporter.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Instead, the components complement each other:</span><span style=" font-size:12pt"> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif"><strong>Prometheus Blackbox Exporter</strong> — HTTP, HTTPS, TCP, ICMP, DNS and other standard protocols</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif"><strong>DomProbe</strong> — Native Domino NRPC availability and optional database access</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif"><strong>DomProm</strong> — Domino server statistics, replication, mail routing, performance and health metrics</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif"><strong>node_exporter</strong> — Operating system metrics</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Together they provide a complete monitoring solution for HCL Domino.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Native Domino Integration</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> DomProbe runs as a native Domino server task on Linux and integrates directly with the Domino runtime using the Domino C API.<br /> The task exposes familiar Prometheus endpoints such as /probe, /metrics, and /health, making integration with existing Prometheus environments straightforward.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Open Source</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> DomProbe closes one of the last remaining gaps in the Prometheus monitoring ecosystem for HCL Domino by bringing native NRPC probing to Prometheus.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> If you're already using Prometheus and Grafana to monitor your Domino infrastructure, DomProbe adds the missing visibility into the protocol that powers Domino itself.</span><span style=" font-size:12pt"> </span><span style=" font-size:12pt;color:blue"><u><br /> <br /> </u></span><a href="https://github.com/nashcom/domino-blackbox-exporter"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/domino-blackbox-exporter</u></span></a><span style=" font-size:12pt"> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/introducing-domprobe-–-the-missing-piece-for-prometheus-nrpc-monitoring.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/introducing-domprobe-–-the-missing-piece-for-prometheus-nrpc-monitoring.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Meet nshini – A Notes.ini Editing and Conversion Tool</title>
<pubDate>Sun, 5 Jul 2026 12:39:00 +0200</pubDate>
<description>
<![CDATA[ 
If you've administered HCL Domino long enough, you've probably edited notes.ini more times than you can count. It looks like a simple text file—but it isn't. notes.ini is stored in LMBCS, a Lotus-sp ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/meet-nshini-–-a-notes.ini-editing-and-conversion-tool.htm</link>
<category>notes.ini</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/meet-nshini-–-a-notes.ini-editing-and-conversion-tool.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/meet-nshini-–-a-notes.ini-editing-and-conversion-tool.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif">If you've administered HCL Domino long enough, you've probably edited notes.ini more times than you can count. It looks like a simple text file—but it isn't.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> notes.ini is stored in <strong>LMBCS</strong>, a Lotus-specific character encoding.<br /> Modern editors expect UTF-8. While ASCII-only settings are usually safe, any non-ASCII value—passwords, international characters, or localized paths—can be silently corrupted simply by opening and saving the file in a standard editor.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> That's exactly why I created <strong>nshini</strong> after working with another HCL partner on one of his support tickets.<br /> In his case support asked him to make changes to the notes.ini which broke umlauts.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> nshini transparently converts notes.ini between LMBCS and UTF-8 using the official Domino C API. You edit a normal UTF-8 file in your preferred editor, and the tool safely converts everything back when you're done.<br /> <br /> This makes working with notes.ini much more comfortable on both <strong>clients and servers</strong>.<br /> When changing settings on a server you can always use &quot;<strong>set config</strong>&quot;.<br /> <br /> On Windows, nshini integrates seamlessly with <strong>Notepad++</strong>, allowing you to use one of the best text editors available, complete with syntax highlighting, search, and visual diff support.<br /> On Linux, it works equally well with your favorite editor while providing clean UTF-8 output for scripts and command-line tools.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Beyond editing, converting notes.ini to UTF-8 opens the door to modern tooling. Configuration can be compared with standard diff tools, processed by scripts, indexed, or even analyzed by AI workflows without worrying about legacy character encoding.<br /> nshini also provides commands to read and update notes.ini variables through the Domino API, making it useful for automation as well as interactive administration.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The project is open source and available on GitHub:</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> GitHub:</strong> </span><a href=https://github.com/nashcom/nshini><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/nshini</u></span></a><span style=" font-size:12pt"> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/meet-nshini-–-a-notes.ini-editing-and-conversion-tool.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/meet-nshini-–-a-notes.ini-editing-and-conversion-tool.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Domino NRPC Proxy – A Modern Proxy Platform for Domino</title>
<pubDate>Sun, 5 Jul 2026 12:13:09 +0200</pubDate>
<description>
<![CDATA[ 
The Domino NRPC Proxy project started with a simple but ambitious goal: provide a modern, production-ready proxy for Domino NRPC connections that integrates naturally with Docker and Kubernetes. Wh ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-nrpc-proxy-–-a-modern-proxy-platform-for-domino.htm</link>
<category>Docker</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-nrpc-proxy-–-a-modern-proxy-platform-for-domino.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/domino-nrpc-proxy-–-a-modern-proxy-platform-for-domino.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The <strong>Domino NRPC Proxy</strong> project started with a simple but ambitious goal: provide a modern, production-ready proxy for Domino NRPC connections that integrates naturally with Docker and Kubernetes.<br /> <br /> While traditional TCP proxies can forward NRPC traffic, they have no understanding of the Domino protocol itself.<br /> At the heart of the project is a custom <strong>NGINX Stream module</strong> that understands the initial Domino NRPC handshake and enables intelligent routing based on the requested Domino server.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Since then, the project has grown well beyond its original scope.<br /> Today it provides a complete proxy platform for Domino, combining NRPC routing, HTTPS reverse proxy support, generic stream proxying.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Key Features</strong></span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Custom <strong>NGINX Stream module</strong> for Domino NRPC</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Intelligent NRPC routing based on the requested Domino server</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">HTTPS reverse proxy support</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Generic TCP stream proxy support</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Optional ACME certificate management using LEGO</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Dynamic configuration generation from templates</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Zero-downtime configuration updates</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Automatic certificate reload</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Native Docker and Kubernetes support</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Docker Secrets and Kubernetes Secrets integration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Environment variable driven configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Own Prometheus metrics endpoint including details about configuration status</span></li></ul><span style=" font-size:10pt;font-family:sans-serif">The container build compiles NGINX and the stream module. The Image can be build with the included build script. The image is also available on the GitHub registry as part of the GitHub project.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Intelligent NRPC Routing</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The Domino NRPC Proxy is much more than a TCP forwarder.<br /> The project includes a custom NGINX Stream module developed specifically for Domino NRPC. The module understands the initial NRPC protocol exchange and extracts the Domino server name requested by the Notes client.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This information is then used to make an intelligent routing decision before forwarding the connection to the appropriate back-end Domino server.<br /> The entire process is completely transparent to the client and requires no changes to existing Notes or Domino installations.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> This makes it possible to:</span><span style=" font-size:12pt"> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Publish a single NRPC endpoint for multiple Domino servers.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Route Notes clients automatically to the requested server.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Hide backend Domino servers inside private Docker or Kubernetes networks.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Dynamically route connections as infrastructure changes.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Simplify load balancer configurations.</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Scale from a single Domino server to large Domino deployments.</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> This capability is particularly valuable in Kubernetes environments, where Domino servers are represented by services and pods whose network topology may change over time.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> HTTPS Reverse Proxy</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> Although NRPC remains the primary focus of the project, most Domino environments also expose HTTP and HTTPS services.<br /> The Domino NRPC Proxy now includes a fully integrated HTTPS reverse proxy based on NGINX.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Features include:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">HTTPS reverse proxy</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">HTTP to HTTPS redirection</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Multiple virtual hosts</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Configurable upstream servers</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Dynamic configuration generation</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> Running both NRPC and HTTPS within the same proxy simplifies deployments while providing a consistent operational model.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Generic Stream Proxy Support</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The custom NRPC module is one part of the project.<br /> The surrounding infrastructure has been designed to support generic TCP stream proxying as well.<br /> This allows the same container to proxy additional TCP services using the same configuration framework, making the project useful beyond Domino-specific scenarios.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Designed for Docker and Kubernetes</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The project was designed from day one with containers in mind.<br /> Whether you're deploying a single Domino server with Docker Compose or operating a large Kubernetes cluster, the same container image can be used without modification.<br /> Configuration is generated automatically during startup, allowing deployments to be driven entirely by environment variables and secrets.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The result is a container that fits naturally into Infrastructure-as-Code workflows and automated deployments.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Dynamic Configuration Templating</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> Maintaining multiple static NGINX configuration files quickly becomes difficult as deployments grow.<br /> Instead, the Domino NRPC Proxy gene7rates its configuration dynamically from templates.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The templating system supports:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">HTTP configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Stream configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Environment variable substitution</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Optional feature enablement</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">User supplied templates</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Deployment specific customization</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> This approach keeps the container image generic while allowing extensive customization without rebuilding images.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Zero-Downtime Configuration Updates</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> Container environments are dynamic by nature.<br /> Services may be added, removed or updated while the proxy continues running.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Whenever configuration changes are detected, the proxy automatically:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Generates the new configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Validates it using nginx -t</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Atomically replaces the active configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Reloads NGINX without interrupting existing client sessions</span></li></ul><span style=" font-size:10pt;font-family:sans-serif">Existing NRPC and HTTPS connections continue uninterrupted while new connections immediately use the updated configuration.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Automatic Certificate Management</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The latest versions add optional integrated ACME support using the excellent <strong>LEGO</strong> client.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The proxy can automatically request and renew certificates from Let's Encrypt or any RFC 8555 compatible ACME provider.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Supported features include:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Let's Encrypt Production and Staging</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Alternative ACME providers</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">HTTP-01 challenge support</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Automatic renewals</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Environment variable based configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Automatic NGINX reload after successful renewal</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Support LEGO environment configuration</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The implementation also handles the initial bootstrap process, allowing completely unattended deployments.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Automatic Certificate Reload</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> Certificates may also be provided by external certificate management solutions.<br /> The Domino NRPC Proxy automatically detects updated certificates and reloads NGINX without requiring container restarts.<br /> This enables continuous certificate management without downtime or maintenance windows.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Secret Integration</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> Security is an important design goal.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Sensitive configuration data should never be embedded in container images.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The Domino NRPC Proxy provides native support for:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Docker Secrets</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Kubernetes Secrets</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Certificates, private keys, bearer tokens, API credentials and other sensitive configuration can be securely mounted while remaining fully compatible with the templating framework.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Built Around Automation</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> One of the guiding principles throughout the project has been automation.<br /> A modern infrastructure component should require as little manual configuration as possible.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The Domino NRPC Proxy therefore focuses on:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Convention over configuration</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Environment variable driven deployments</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Dynamic configuration generation</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Automated certificate management</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Automatic configuration validation</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Zero-downtime updates</span></li></ul><span style=" font-size:10pt;font-family:sans-serif">The result is a proxy that is equally at home in a simple Docker installation or a fully automated Kubernetes platform.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Part of the Domino Infrastructure Ecosystem</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The Domino NRPC Proxy has become one of the core building blocks of a larger Domino infrastructure ecosystem.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> It integrates naturally with projects such as:</span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Domino Fleet Manager</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Cube Control</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">CertMgr</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Domino monitoring components</span></li></ul><span style=" font-size:10pt;font-family:sans-serif">Each project is designed to work independently, while together they provide a modern platform for deploying, managing and operating HCL Domino environments.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> <br /> Open Source</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> <br /> The Domino NRPC Proxy is available as an open source project on GitHub:</span><span style=" font-size:12pt"> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://github.com/nashcom/domino-nrpc-proxy"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/domino-nrpc-proxy</u></span></a><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The project has evolved considerably since its first release and continues to grow with new features and deployment options.<br /> If you're running Domino in Docker, Kubernetes, or simply looking for a modern proxy platform for Domino services, I hope you'll find it useful.</span><span style=" font-size:12pt"> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/domino-nrpc-proxy-–-a-modern-proxy-platform-for-domino.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/domino-nrpc-proxy-–-a-modern-proxy-platform-for-domino.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Behind the Scenes: Linux Install Fest Lab at Engage 2026</title>
<pubDate>Tue, 28 Apr 2026 09:20:23 +0200</pubDate>
<description>
<![CDATA[ 
Bill, Matijn and I did three hands on sessions at Engage. If you wondered how we have been doing it. Here is how this worked and it could be leveraged for own workshops. Using cloud hosted servers ca ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm</link>
<category>Enagage</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">Bill, Matijn and I did three hands on sessions at Engage.<br /> If you wondered how we have been doing it. Here is how this worked and it could be leveraged for own workshops.</span> <br /><span style=" font-size:10pt;font-family:sans-serif">Using cloud hosted servers can make a lot of sense. And it is very cost efficient.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">Hetzner is a provider with a very modern and easy to use GUI. But they also have a great API to create and manage servers.</span> <br /><span style=" font-size:10pt;font-family:sans-serif">I am using them for years for DNUG and other events. And I would make it available for friends &amp; family.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">Recently Hetzner moved their separate DNS API into the central cloud API --&gt;</span><a href=https://docs.hetzner.cloud/reference/cloud><span style=" font-size:10pt;color:blue;font-family:sans-serif">https://docs.hetzner.cloud/reference/cloud</span></a> <br /><span style=" font-size:10pt;font-family:sans-serif">I took this opportunity to implement most of this API in an existing Lotus Script class (Script Lib) and read the full inventory for a project to manage it from a Notes database.<br /> Each database would match 1:1 a Hetzner project. We created a private network for the project and offered services like NFS based file mounts to provide workshop data.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">The database is mainly designed for lab setups with the same server configuration used for all servers.</span> <br /><span style=" font-size:10pt;font-family:sans-serif">A profile document is used to define the type, size, location etc of the server.</span> <br /><span style=" font-size:10pt;font-family:sans-serif">What I also added is support for cloud.init configurations.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">For our servers I just needed a host name. The e-mail address is used for an integrated mail workflow to notify users -- including sending them their server name and IP.<br /> When creating a new server also a DNS record is created and also the IN-ARPA entry is set properly.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">Creating a new server just takes a couple of seconds. In our case you have to wait a moment because we installed additional software, configured a NFS mount and rebooted the machine.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">Because we did not expect everyone to register ahead of time thru the official Engage registration processing a mail flow from the Leap App to our database, I added a registration form to feed in new server requests directly.<br /> The slides had a registration QR code to fill in the registration code.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">This gave us a very flexible way to generate new servers on-the-fly.<br /> <br /> The whole lab setup was done in a reusable way. So all the time spent on it wasn't just for this one conference.<br /> And I will extend it over time for other use cases. The Lotus Script Lib is the core of the application, but with my additions also reading the inventory could be re-used in other areas.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">This is a good example use case for a Notes database. It would probably have taking me much longer with most other approaches.<br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">See some details below. I also added label support and to specify firewalls directly or via labels.<br /> The could.init replaced my earlier Ansible scripting I used to customize servers after they are created.</span> <br /><span style=" font-size:10pt;font-family:sans-serif">But I also added a Ansible host list export and we used the same SSH key for all servers beside the management server which hosted the file shares.</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">-- Daniel</span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">&nbsp; &nbsp;</span><img  alt="Image:Behind the Scenes: Linux Install Fest Lab at Engage 2026" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm/content/M2?OpenElement" /><span style=" font-size:10pt;font-family:sans-serif"> &nbsp; &nbsp; &nbsp;</span><img  alt="Image:Behind the Scenes: Linux Install Fest Lab at Engage 2026" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm/content/M3?OpenElement" /> <br /> <br /> <br /><img  alt="Image:Behind the Scenes: Linux Install Fest Lab at Engage 2026" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm/content/M4?OpenElement" />  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/behind-the-scenes-linux-install-fest-lab-at-engage-2026.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Domino On Proxmox LXC Containers Part II</title>
<pubDate>Fri, 24 Apr 2026 20:12:33 +0200</pubDate>
<description>
<![CDATA[ 
As mentioned at Engage, I am working on Domino container deployments on Proxmox. The first deliverable was a new build option for the container image to create two components: A LXC template whic ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm</link>
<category>Proxmox</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif">As mentioned at Engage, I am working on Domino container deployments on Proxmox.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The first deliverable was a new build option for the container image to create two components:</span><span style=" font-size:12pt"> <br /> <br /> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">A LXC template which can be cloned into a new LXC container using pct command line</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">A /opt volume which is read-only mounted into each container</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> You can see from the configuration dump below how this would look like.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The second deliverable is a management script &quot;dompct&quot; which allows to create and manage LXC containers.<br /> I added some screen shots below. </span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The new script is already part of the develop branch of the Domino Start script, but I am still enhancing and testing it.<br /> It comes with configuration profiles which can be managed and assigned to servers when created.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This includes ZFS volumes assigned to LXC containers -- as you can also see from the example below.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The new option <strong>build.sh -pct</strong> and the new <strong>dompct</strong> tool standardize and simplify Proxmox LXC deployments.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There isn't full documentation yet in the GitHub project. But dompct has command line help already.<br /> You can either use command-line parameters or the menu. <br /> The menu prompts to select a container if not specified. Or a profile if not specified.<br /> It also prompts for the hostname when creating a new container and the hostname is not specified at command-line.<br /> <br /> The tool can be used interactively or for automated provisioning. That's why I also added <strong>-json</strong> for output.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The Proxmox LXC is a first implementation and I mainly wrote it for one customer who is actively looking into Domino on Proxmox deployments.<br /> But I wanted to make it available already for feedback.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> --- Configuration output ---</strong></span><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> --------------------------------------------------------------------------------</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> Config LXC 800</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> --------------------------------------------------------------------------------</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> arch: amd64</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> cores: 4</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> features: nesting=1</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> hostname: domino-01</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> memory: 8192</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt;color:red"><strong><br /> mp0: /rpool/data/domino-opt-20260419-1053,mp=/opt,ro=1</strong></span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt;color:blue"><strong><br /> mp1: /rpool/data/subvol-800-domino-local,mp=/local</strong></span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> mp2: /rpool/data/subvol-800-domino-nsf,mp=/local/notesdata</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> mp3: /rpool/data/subvol-800-domino-translog,mp=/local/translog</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> mp4: /rpool/data/subvol-800-domino-daos,mp=/local/daos</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> mp5: /rpool/data/subvol-800-domino-backup,mp=/local/backup</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> net0: name=eth0,bridge=vmbr0,hwaddr&frac14;:24:11:75:9A:30,ip=dhcp,type=veth</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> ostype: ubuntu</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> rootfs: local-zfs:subvol-800-disk-0,size=20G</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> swap: 0</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> tags: domino</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> unprivileged: 1</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> description:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> HCL Domino server 800</span></tt><span style=" font-size:12pt"> <br /> <br /> <br /> </span><img  alt="Image:Domino On Proxmox LXC Containers Part II" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> <br /> <br /> </span><img  alt="Image:Domino On Proxmox LXC Containers Part II" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm/content/M3?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> --- Configuration profile example ---</strong></span><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:10pt"><br /> <br /> # Domino LXC configuration - default</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> PCT_TAGS=domino</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_DATA_POOL=rpool/data</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_DAOS_POOL=rpool/data</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_TRANSLOG_POOL=rpool/data</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> PCT_TRANSLOG_SIZE_GB=5</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_NSF_SIZE_GB=100</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_BACKUP_SIZE_GB=100</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_DAOS_SIZE_GB=100</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> PCT_RAM_GB=8</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_SWAP_GB=0</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> PCT_CPU=4</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> env_DOMSETUP_ENABLED=1</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> env_NODE_EXPORTER_OPTIONS=default</span></tt><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:10pt"><br /> <br /> PCT_NET0_TEMPLATE=name=eth0,bridge=vmbr0,ip=%PCT_IP%/24,gw=192.168.96.98</span></tt><span style=" font-size:12pt"> <br /> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> --- Command Line Parameters ---</strong></span><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:10pt"><br /> <br /> dompct - LXC Container Control Utility</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Usage:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  ./dompct.sh &lt;command&gt; &#91;VMID&#93; &#91;options&#93;</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Commands:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  create &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Create new container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  start &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Start container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  stop &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Stop container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  status &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Show container status</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  enter | bash &nbsp; &nbsp; &nbsp; &nbsp;Enter container shell</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  config &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Show container configuration</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  update &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Update container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  destroy &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Destroy container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  about &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Show container information</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  profile &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Select or apply profile</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  list &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;List containers</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  KILL &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Force kill container</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  KILL-WITH-DISKS &nbsp; &nbsp; Kill container and remove disks</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Global Options:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  -profile=&lt;name&gt; &nbsp; &nbsp; Use profile (from ~/.dompct/*.cfg)</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -host=&lt;name&gt; &nbsp; &nbsp; &nbsp; &nbsp;Set hostname</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -hostname=&lt;name&gt; &nbsp; &nbsp;Same as -host</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -tags=&lt;tags&gt; &nbsp; &nbsp; &nbsp; &nbsp;Set Proxmox tags (comma-separated)</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -ip=&lt;ip&gt; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Assign IP address</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -description=&lt;txt&gt; &nbsp;Set container description</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  -opt-vol=&lt;opts&gt; &nbsp; &nbsp; Volume options (advanced)</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Output Options:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  -json &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Output in JSON format (where supported)</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Arguments:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  VMID &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Numeric container ID (required for most commands)</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Examples:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  ./dompct.sh list</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  ./dompct.sh start 800</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  ./dompct.sh create -profile=mail</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  ./dompct.sh profile</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  ./dompct.sh destroy 800</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br /> Notes:</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> <br />  - If VMID is omitted, interactive menu may be used</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br />  - Profiles are stored in: ~/.dompct/</span></tt><span style=" font-size:12pt"> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/domino-on-proxmox-lxc-containers-part-ii.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-lxc-containers-part-ii.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Ubuntu 26.04 LTS released with a last minute surprise -- Kernel 7.0</title>
<pubDate>Thu, 23 Apr 2026 23:32:08 +0200</pubDate>
<description>
<![CDATA[ 
Today finally the release shipped and they just updated the website and also provided all ISO images. I have been using the release candidate for a while natively and for Docker containers. Deskto ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm</link>
<category>Ubuntu</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">Today finally the release shipped and they just updated the website and also provided all ISO images.<br /> I have been using the release candidate for a while natively and for Docker containers.</span> <br /> <br /> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Desktop</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Server</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">WSL</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Container Image default for <strong>ubuntu</strong> is also version 26.04.</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> --- Kernel ---</strong></span><span style=" font-size:12pt"> </span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif"><br /> The RC kernel was: <strong>6.19.0-9-generic</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The released kernel : <strong>7.0.0-14-generic</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> --- GLIBC ---</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> GLIBC is also very up to date: (Ubuntu GLIBC 2.43-2ubuntu2) <strong>2.43</strong></span><span style=" font-size:12pt"> <br /> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The main challenge here is a major new kernel release.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The change isn't as big as it sounds on top of the latest 6.19. <br /> Ubuntu might have waiting for the kernel to be released and updated it because of newer CPU support in kernel 7.0 which they wanted to be prepared for.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> But this raises questions for Domino on Ubuntu 26.04 LTS.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I would not update any production environments yet.<br /> This is way too new. But it works well in my personal testing. </span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> If you give it a try in a test environment I would be interested in your findings. <br /> But given the major kernel update, I would really wait for any production deployment.</span><span style=" font-size:12pt"> <br /> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Official release statement for 14.5.1</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://support.hcl-software.com/csm?id=kb_article&amp;sysparm_article=KB0128491"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://support.hcl-software.com/csm?id=kb_article&amp;sysparm_article=KB0128491</u></span></a><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Equivalent OS with the following kernel/packages:</span><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:10pt"><br /> kernel-6.12.0-55.9.1.el10_0.x86_64 or higher 6.12 kernel</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> glibc-2.39-37.el10.x86_64 or higher</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:10pt"><br /> libstdc++-14.2.1-7.el10.x86_64 or higher</span></tt><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> You can see that from Kernel level and also GLIBC level Ubuntu 26.04 is quite more current then what is listed as officially tested and supported for Domino.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Note about Ubuntu system requirements</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There has been a change in system requirements for the deskop. The hardware resource requirements have been bumped up a bit.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> On the server side the hardware resource requirements did not change. 1,5 GB is still a pretty low requirement.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> With Domino I would at least have 4 GB for a small server anyhow. But the 1,5 GB show the low resource requirements a Linux server has -- on top of the application requirements.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> </span><span style=" font-size:12pt"><br /> </span><img  alt="Image:Ubuntu 26.04 LTS released with a last minute surprise -- Kernel 7.0" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/ubuntu-26.04-lts-released-with-a-last-minute-surprise-kernel-7.0.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Engage 2026 Presentation Slides Leveraging CertMgr and Resources</title>
<pubDate>Thu, 23 Apr 2026 22:10:11 +0200</pubDate>
<description>
<![CDATA[ 
As promised at Engage this week, here is my presentation including additional material as promised in the session. The Script Lib is a first version which I wrote for one of my projects to integrate ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/engage-2026-presentation-slides-leveraging-certmgr-and-resources.htm</link>
<category>CertMgr</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/engage-2026-presentation-slides-leveraging-certmgr-and-resources.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/engage-2026-presentation-slides-leveraging-certmgr-and-resources.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> As promised at Engage this week, here is my presentation including additional material as promised in the session.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The Script Lib is a first version which I wrote for one of my projects to integrate certificate management.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I am happy to share it and I am looking forward to feedback.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> What I also added is the code I used in my demo to integrate with HashiCorp.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> For the presentation I also setup a new HashiCorp development project which might help to get started with HashiCorp.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The HashiCorp instance I was using in my demo has been automatically setup using this project.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This includes the provisioners for ACME and API level integration.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I hope the resources help you to get started with your own integrations.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> HashiCorp is an interesting option for certifcate management inside a company.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This includes ACME support and also the secrets engine to securely distribute secrets like TLS private keys.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> -- Daniel</span><span style=" font-size:12pt"> <br /> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Engage Presentation slides</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://github.com/HCL-TECH-SOFTWARE/domino-cert-manager/blob/main/presentations/engage_2026_certmgr.pdf"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/HCL-TECH-SOFTWARE/domino-cert-manager/blob/main/presentations/engage_2026_certmgr.pdf</u></span></a><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Example Integration: CertMgr HashiCorp</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://opensource.hcltechsw.com/domino-cert-manager/hashicorp/"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://opensource.hcltechsw.com/domino-cert-manager/hashicorp/</u></span></a><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Script Lib Source code</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://github.com/HCL-TECH-SOFTWARE/domino-cert-manager/tree/main/resources"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/HCL-TECH-SOFTWARE/domino-cert-manager/tree/main/resources</u></span></a><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> HashiCorp Deployment Project to get started with HashiCorp</strong></span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://github.com/nashcom/nsh-vault-deploy"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/nsh-vault-deploy</u></span></a><span style=" font-size:12pt"> </span> <br /> <br />  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/engage-2026-presentation-slides-leveraging-certmgr-and-resources.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/engage-2026-presentation-slides-leveraging-certmgr-and-resources.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Performance Challenges on modern Intel Hybrid CPUs with Notes and other applications</title>
<pubDate>Thu, 16 Apr 2026 10:13:46 +0200</pubDate>
<description>
<![CDATA[ 
After moving to a new notebook, my Notes client got very slow when I was in a Sametime meeting or ran other a bit more CPU intensive tasks. It turns out that Windows is giving the Notes client the sl ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/performance-challenges-with-modern-intel-hybrid-cpus-with-notes-and-other-applications.htm</link>
<category>Notes</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/performance-challenges-with-modern-intel-hybrid-cpus-with-notes-and-other-applications.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/performance-challenges-with-modern-intel-hybrid-cpus-with-notes-and-other-applications.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">After moving to a new notebook, my Notes client got very slow when I was in a Sametime meeting or ran other a bit more CPU intensive tasks.<br /> It turns out that Windows is giving the Notes client the slower E-Core CPU cores, which results in a very slow UI responsiveness.</span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> HCL is aware of this and we had a call last week.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> If you are running a modern Intel CPU on your workstation/notebook you should read this link for detailed information and a tool</span><span style=" font-size:12pt"><br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href=https://github.com/nashcom/nshcpuset><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/nshcpuset</u></span></a><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> I wrote up all the technical details and a small troubleshooting and work-around tool.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> My take away from this is that we have to watch more for the CPU P-Cores then the total number of cores a modern CPU has.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The notebook I got has 2 physical P-Cores with Hyper-Threading + 8 E-Cores.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This doesn't hit Notes alone! We had interesting experiences with VMware workstation before they looked into it.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Darren blogged about the VMware issues he ran into &nbsp;</span><a href="https://blog.darrenduke.net/darren/ddbz.nsf/dx/type-2-hypervisors-and-the-evils-of-e-cores.htm"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://blog.darrenduke.net/darren/ddbz.nsf/dx/type-2-hypervisors-and-the-evils-of-e-cores.htm</u></span></a><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> I am not a fan of Processor Lasso and looked into the APIs on my own to get a clear picture.<br /> Processor Lasso is a too big tool with a lot of options.<br /> You can also use it, but the easier path is to use my small program. <br /> <br /> -- Daniel</span><span style=" font-size:12pt"> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/performance-challenges-with-modern-intel-hybrid-cpus-with-notes-and-other-applications.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/performance-challenges-with-modern-intel-hybrid-cpus-with-notes-and-other-applications.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Domino on Proxmox deployment models</title>
<pubDate>Wed, 15 Apr 2026 16:17:10 +0200</pubDate>
<description>
<![CDATA[ 
With the current cost increases for VMware licenses and also hardware some of my customers start to look very seriously for alternate solutions. One deployment method would be Proxmox with local ZFS ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-deployment-models.htm</link>
<category>Proxmox</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-deployment-models.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-deployment-models.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> With the current cost increases for VMware licenses and also hardware some of my customers start to look very seriously for alternate solutions.<br /> One deployment method would be Proxmox with local ZFS disks.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> ZFS is a very interesting file-system and volume manager combined. It offers a lot of flexibility and choices. <br /> Compression, de-duplication, optimized record size, snapshots, encryption and more benefits.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> I am a big fan for a while and I did blog about Domino on Proxmox before.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Last weekend I looked into different deployment methods for Domino on Proxmox for a customer.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> A VM with Linux + Docker + Domino might be additional overhead which could be optimized.<br /> <br /> LXC containers use native ZFS volumes and are very efficient:</span><span style=" font-size:12pt"> <br /> <br /> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Lightweight Linux instance with shared kernel like Docker</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Leverage ZFS host subvolumes for a true end to end storage management and less overhead</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">Standardized OS images</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> What is missing is the automated installation we know from Docker.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I am looking into that right now and if you are interested in Domino on Proxmox, I want to hear from you.<br /> <br /> At Engage I will show case Domino on Proxmox. I will bring a Proxmox server running on my notebook with an automated Domino installation including management scripts with me.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I would like to hear from you what type of deployments you are looking into.<br /> <br /> We are working on multiple deployment options optimized for Proxmox in combination with Domino clustering to optimize the deployment footprint.<br /> This includes DAOS storage deduplication cross servers and backup.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> -- Daniel</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> My Notebook deployment on VMware workstation with Proxmox 4 CPU cores + 8 RAM as a test/demo installation for on the road.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> For LXCs it does not even need the hardware support. </span><span style=" font-size:12pt"><br /> <br /> </span><img  alt="Image:Domino on Proxmox deployment models" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-deployment-models.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/domino-on-proxmox-deployment-models.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/domino-on-proxmox-deployment-models.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Join Us at Engage 2026: Domino on Linux, Installfest and CertMgr</title>
<pubDate>Tue, 14 Apr 2026 19:22:49 +0200</pubDate>
<description>
<![CDATA[ 
Engage Conference 2026 is just around the corner. A quick look at the agenda reveals several Linux-focused sessions—and that’s no coincidence. Linux continues to play a key role in sovereign and ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm</link>
<category></category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm</guid>
<content:encoded><![CDATA[  <table width=1599 style="border-collapse:collapse;"> <tr valign=top height=8> <td width=554 style="border-style:none none none none;border-color:#000000;border-width:0px 0px 0px 0px;padding:1px 1px;"><span style=" font-size:10pt;font-family:sans-serif">Engage Conference 2026 is just around the corner.<br /> <br /> A quick look at the agenda reveals several Linux-focused sessions—and that’s no coincidence.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Linux continues to play a key role in sovereign and future-proof solutions. As in previous years, Bill is hosting the popular Domino on Linux round table.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> In addition, the conference will feature a Linux desktop session along with a series of Domino on Linux Installfest sessions. These sessions can be attended independently, but they are also designed to complement each other and build progressively.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Bill, Martijn and I have teamed up to present a full range of sessions—from beginner through to expert level. This includes hands-on labs using on-demand virtual machines at Hetzner, along with forward and reverse DNS within our domino-lab.net environment.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Even if you can’t attend the Installfest sessions, the Linux round table is highly recommended. It’s a great opportunity to ask questions, share feedback, and connect with others—especially if you’re already running Domino on Linux or planning to explore it. For example on Proxmox.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> We’ll also share updates on what has been developed over the past year, along with a new initiative aimed at making Domino on Linux more accessible for administrators.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> As part of this effort, a new repository has been launched as a central entry point into the Domino on Linux ecosystem:</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> https://nashcom.github.io/nsh-domino-linux/</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Beyond the Linux sessions, I will present another session on Domino CertMgr. If certificate management and automation are topics of interest, this session should definitely be on your list.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> You can explore the full agenda here:</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> https://engage.ug/pages/session2026</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> We are looking forward to seeing you at Engage 2026.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Bill | Martijn | Daniel</span><span style=" font-size:12pt"> </span> <td width=513 style="border-style:none none none none;border-color:#000000;border-width:0px 0px 0px 0px;padding:1px 1px;"><img  alt="Image:Join Us at Engage 2026: Domino on Linux, Installfest and CertMgr" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm/content/M2?OpenElement" /> <td width=526 style="border-style:none none none none;border-color:#000000;border-width:0px 0px 0px 0px;padding:1px 1px;"><img  alt="Image:Join Us at Engage 2026: Domino on Linux, Installfest and CertMgr" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm/content/M3?OpenElement" /></table> <p style="margin-top:0px;margin-Bottom:0px"></p> <br /><span style=" font-size:12pt"><br /> <br /> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/join-us-at-engage-2026-domino-on-linux-installfest-and-certmgr.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Certificate Lifetimes Are Shrinking — Is Your Domino Infrastructure Ready?</title>
<pubDate>Mon, 30 Mar 2026 23:24:07 +0200</pubDate>
<description>
<![CDATA[ 
Certificate maximum lifetimes dropped to 200 days in March 2026 and will reach 47 days by 2029. At that frequency, manual renewal becomes operationally impossible. HCL Domino CertMgr automates issuan ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/certificate-lifetimes-are-shrinking-is-your-domino-infrastructure-ready.htm</link>
<category>CertMgr</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/certificate-lifetimes-are-shrinking-is-your-domino-infrastructure-ready.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/certificate-lifetimes-are-shrinking-is-your-domino-infrastructure-ready.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">Certificate maximum lifetimes dropped to 200 days in March 2026 and will reach 47 days by 2029.<br /> At that frequency, manual renewal becomes operationally impossible. HCL Domino CertMgr automates issuance and renewal end-to-end.<br /> This includes certificate rollover and also key rollover -- which is as important as rolling over certificates and often overlooked in current discussions.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> For everything outside Domino — NGINX, load balancers, and other services — there is a need for automated certificate management.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Rotating the private key on every renewal cycle is the part most deployments have not solved yet.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Here is a longer document I wrote up for one of the projects with additional details:</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:12pt;color:blue"><u><br /> </u></span><a href="https://github.com/nashcom/srvguard/blob/main/docs/certificate-lifetime-reduction.md"><span style=" font-size:10pt;color:blue;font-family:sans-serif"><u>https://github.com/nashcom/srvguard/blob/main/docs/certificate-lifetime-reduction.md</u></span></a><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This initiative started last week. The timing is not a coincident. It's in time for my Engage presentation and the latest changes for certificate lifetime.<br /> <br /> When HCL introduced CertMgr in Domino 12.0 most of the feature we have today have been already present.<br /> Domino 12.0.1 introduced export / import which might be helpful for automation. <br /> <br /> CertMgr and certstore.nsf are built on open standards and importing certificates/keys and handling CSRs for an automated flow are straightforward to implement on Domino CertMgr side.<br /> The challenge is most time the CA side. My previous post shows a straightforward HashiCorp configuration using ACME as the protocol. <br /> But there are also other easy to use ways to integrate with modern CAs.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There is more to come. But I want to keep also some news for my conference session.<br /> If you are curious what is coming you can take a look at the referenced projects.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> -- Daniel</span><span style=" font-size:12pt"> <br /> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/certificate-lifetimes-are-shrinking-is-your-domino-infrastructure-ready.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/certificate-lifetimes-are-shrinking-is-your-domino-infrastructure-ready.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>HashiCorp ACME with Domino CertMgr – a Beautiful Combination</title>
<pubDate>Mon, 30 Mar 2026 22:59:58 +0200</pubDate>
<description>
<![CDATA[ 
For my upcoming session at HCL Engage next month, I’ve been looking into additional integrations for Domino CertMgr. The guiding principle is simple: use standards wherever possible. One of the most i ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm</link>
<category>CertMgr</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif">For my upcoming session at HCL Engage next month, I’ve been looking into additional integrations for Domino CertMgr. The guiding principle is simple: <strong>use standards wherever possible</strong>.<br /> One of the most important standards in this space is ACME. It has become the default protocol for automated certificate lifecycle management and is supported by virtually every modern toolchain.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Vault as an enterprise ACME CA</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> HashiCorp Vault is a modern, API-first PKI solution widely used in corporate environments. With built-in ACME support, Vault can act as a fully functional ACME certificate authority.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> That makes integration straightforward:</span><span style=" font-size:12pt"> <br /> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Vault provides the CA</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">ACME provides the interface</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">CertMgr consumes certificates</span><span style=" font-size:12pt"> <br />  </span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> No custom code, no special handling—just standard protocol.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Why this combination works so well</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Domino CertMgr was designed for automation. Pairing it with Vault via ACME creates a clean and robust setup:</span><span style=" font-size:12pt"> <br /> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">enterprise-grade CA</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">fully automated issuance and renewal</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">standard-based integration</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Current work</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> I’m currently building a streamlined Vault setup to make testing and demos easier, including ACME-enabled configurations out of the box.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> This allows quick validation of:</span><span style=" font-size:12pt"> <br /> </span> <ul> <li><span style=" font-size:10pt;font-family:sans-serif">Domino integrations</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">short-lived certificates</span><span style=" font-size:12pt"> </span> </li><li><span style=" font-size:10pt;font-family:sans-serif">policy-driven issuance</span></li></ul><span style=" font-size:10pt;font-family:sans-serif"><br /> Some of this will be shown at Engage conference.</span><span style=" font-size:12pt"> <br /> <br /> <br /> </span><img  alt="Image:HashiCorp ACME with Domino CertMgr – a Beautiful Combination" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm/content/M2?OpenElement" />  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/hashicorp-acme-with-domino-certmgr-a-beautiful-combination.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Explaining the Domino CScan token</title>
<pubDate>Wed, 25 Mar 2026 00:43:39 +0200</pubDate>
<description>
<![CDATA[ 
Now that ClamAV integration shipped in 14.5.1 hopefully more admins look into CScan. CScan for mail flow scan is very straightforward to configure. The configuration database document now defaults to ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/explaining-the-domino-cscan-token.htm</link>
<category>CScan</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/explaining-the-domino-cscan-token.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/explaining-the-domino-cscan-token.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> Now that ClamAV integration shipped in 14.5.1 hopefully more admins look into CScan.<br /> CScan for mail flow scan is very straightforward to configure. The configuration database document now defaults to ClamAV with the default parameters.</span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There some details about the implementation which are not well known but eventually good to know.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There is a Scan Token added when the document is scanned. This token avoids rescan the document on the next hup as long the virus scan signature does not change.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">Technically the token is a JWT which you can decode and read. Each server creates a key stored in it's CScan server document.<br /> The key is encrypted for the server and there is a public key to validate the token.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> The token contains the information about the server and time when the document was scanned, a hash, a thumb print of the signing key to find the right signing key.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> It contains also the scan version and pattern and the configuration.<br /> There is also a hash built based on the attachments in some way to avoid re-scanning and to check if attachments changed.<br /> <br /> Here is an example token which could be useful to know:</span><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:9pt"><br /> Field Name: $$CScanToken</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> Data Type: Text</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> Data Length: 644 bytes</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> Seq Num: 1</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> Dup Item ID: 0</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> Field Flags: SUMMARY </span></tt><span style=" font-size:12pt"><br /> </span><tt><span style=" font-size:9pt"><br /> &quot;eyJ0eXAiOiAiSldUIiwgImFsZyI6ICJFZERTQSJ9.eyJ2ZXJzaW9uIjoxLCJpc3N1ZXIiOiJEb21pbm8gQ29udGVudCBTY2FuIiwiY3JlYXRlZCI6IjIwMjYwMzIxVDE5NDE1OSwxMyswMCIsInNlcnZlciI6IkNOPXJheS5sYWIuZG51Zy5ldS9PPWRudWctbGFiIiwic2NhblZlcnNpb24iOiJDbGFtQVYgMS41LjEvMjc5NDciLCJjb25maWdEYiI6IjAwMjU4ODUyMTA3RUQ1NTIiLCJjb25maWdJRCI6IkIyODdDRTBDOUM1N0NCMkUwMDI1OEFCMTAwNTQxNjg1IiwiY29uZmlnTmFtZSI6ImNsYW1hdi1sYWIiLCJ2ZXJpZmljYXRpb25IYXNoIjoiRjJDM0IwOTA1RTAxMjQ0Qzk3Qjg5MDJDNzI3MjVEOUQ4RENDMERGMSIsImtleVRodW1icHJpbnQiOiJzMTFsSUxDeWVfbUk3NEpGZmlkYm5wbWsxY1EiLCJoYXNoQWxnb3JpdGhtIjoiU0hBMSJ9.Pe8ntQ0WaiDH8xksK2gK_8034uRul4qkFWD5GYp1iZKBET1_D-vqsiFs35X0DqUgNCHACWD0wINJ3ErE5OqbAw&quot;</span></tt><span style=" font-size:12pt"> <br /> </span><tt><span style=" font-size:9pt"><br /> ---</span></tt><span style=" font-size:12pt"> <br /> <br /> </span><tt><span style=" font-size:9pt"><br /> {</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;version&quot;: 1,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;issuer&quot;: &quot;Domino Content Scan&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;created&quot;: &quot;20260321T194159,13+00&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;server&quot;: &quot;CN=ray.lab.dnug.eu/O=dnug-lab&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;scanVersion&quot;: &quot;ClamAV 1.5.1/27947&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;configDb&quot;: &quot;00258852107ED552&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;configID&quot;: &quot;B287CE0C9C57CB2E00258AB100541685&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;configName&quot;: &quot;clamav-lab&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;verificationHash&quot;: &quot;F2C3B0905E01244C97B8902C72725D9D8DCC0DF1&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;keyThumbprint&quot;: &quot;s11lILCye_mI74JFfidbnpmk1cQ&quot;,</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br />  &nbsp;&quot;hashAlgorithm&quot;: &quot;SHA1&quot;</span></tt><span style=" font-size:12pt"> </span><tt><span style=" font-size:9pt"><br /> }</span></tt><span style=" font-size:12pt"> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/explaining-the-domino-cscan-token.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/explaining-the-domino-cscan-token.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Revisiting Domino ClamAV for databases on rest</title>
<pubDate>Tue, 24 Mar 2026 16:32:46 +0200</pubDate>
<description>
<![CDATA[ 
Domino 14.5.1 ships native ClamAV mail flow scan in addition to ICAP. The configuration is pretty straightforward as blogged earlier. What is still missing is an periodic/on demand scan of NSF files ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/revisiting-domino-clamav-for-databases-on-rest.htm</link>
<category>ClamAV</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/revisiting-domino-clamav-for-databases-on-rest.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/revisiting-domino-clamav-for-databases-on-rest.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif">Domino 14.5.1 ships native ClamAV mail flow scan in addition to ICAP.<br /> The configuration is pretty straightforward as blogged earlier.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">What is still missing is an periodic/on demand scan of NSF files.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I am revisiting my ClamAV integration on request of two customers.<br /> One doesn't have on rest scan yet. The other one is using a solution which is discontinued soon.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Because I spent all that work already and now Domino also uses ClamAV, it's a good idea to look into it again.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> Tag or quarantine messages?</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">The work I did was almost complete for a first round. What is still open is if we really want to remove attachments and what about quarantining messages.<br /> For now I am just tagging mails and optionally move them to a Virus folder.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Moving out attachments would be a pretty big step for a new feature.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> For the mail flow it looks a bit different, because the mail was never delivered to a user.<br /> <br /> I think for the first step moving to a Virus folder and central reporting would be good?</span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> Logging</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">Now that Domino comes with a nice cscanlog.nsf, I am just reusing what is already available.<br /> I looked at all the fields and provide the same admin experience for the ClamAV on rest scan implementation.<br /> It would be a separate database. Maybe even a separate per scan.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <strong><br /> Looking for the next steps</strong></span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">The solution already supports incremental scans and scans for separate directories.<br /> There is no exclude or wild-card search. But that would be easy to add. Probably better with wildcard support then using lists?</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> I think the first step could be wild-card support. using Unix standard regex. <br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">But eventually I want to also support Domino pattern matching? <br /> What do you think? I could offer both. Bot Unix pattern matching is the more standard approach.</span><span style=" font-size:12pt"> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/revisiting-domino-clamav-for-databases-on-rest.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/revisiting-domino-clamav-for-databases-on-rest.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Domino 14.5.1 AutoUpdate and container update</title>
<pubDate>Fri, 20 Mar 2026 21:48:51 +0200</pubDate>
<description>
<![CDATA[ 
For Linux my clear preference is a container deployment wherever possible. A container only adds a very thin layer on a server and makes updates and consistent installations possible. The container ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm</link>
<category>AutoUpdate</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm</guid>
<content:encoded><![CDATA[  <br /><span style=" font-size:10pt;font-family:sans-serif">For Linux my clear preference is a container deployment wherever possible.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> A container only adds a very thin layer on a server and makes updates and consistent installations possible.<br /> The container image has a lot of customization options.<br /> <br /> I have a couple of customers who are really happy with their container deployment. OK they have me around to add any new option they might need on the fly -- which goes to the open source project as a feature immediately.<br /> Haha I am my best customer for the container deployment. I add new functionality mostly for me. And some features go hand in hand with functionality in the Domino start script.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> But you don't always want or can use containers.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /><span style=" font-size:10pt;font-family:sans-serif">Domino Autoupdate is pretty cool. I just ran it again for 14.5.1 to update all my Windows servers and a coupe of Linux servers.<br /> In my case the Linux servers are mainly native to test autoupdate.</span><span style=" font-size:12pt"> <br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> But AutoUpdate itself has also some helpful information. AutoUpdate provides more detailed information about your servers in one single spot.<br /> It also knows about if the servers run in a container and which container platform is used.<br /> And It also knows for example the account the server runs on.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> </span> <br /> <br /><span style=" font-size:10pt;font-family:sans-serif">On Linux it also provides the glibc version for example.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> None of this information is there by co-incident. I added all those details because they play an important role in the deployment process.<br /> <br /> Another small difference is that Domino servers report their version using a push. Each server is responsible for their own AutoUpdate server document on the central replica.</span><span style=" font-size:12pt"><br /> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> -- Daniel</span><span style=" font-size:12pt"> <br /> <br /> </span><img  alt="Image:Domino 14.5.1 AutoUpdate and container update" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm/content/M2?OpenElement" /><span style=" font-size:12pt"><br /> <br /> <br /> </span><img  alt="Image:Domino 14.5.1 AutoUpdate and container update" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm/content/M3?OpenElement" /><img  alt="Image:Domino 14.5.1 AutoUpdate and container update" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm/content/M4?OpenElement" /><span style=" font-size:12pt"><br /> <br /> </span>  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/domino-14.5.1-autoupdate-and-container-update.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/domino-14.5.1-autoupdate-and-container-update.htm?opendocument&amp;comments</wfw:comment>
</item>
<item>
<title>Domino/Traveler 14.5.1 shipped today - the container image is updated - ClamAV is added to Domino</title>
<pubDate>Thu, 19 Mar 2026 22:36:51 +0200</pubDate>
<description>
<![CDATA[ 
Domino &amp; Traveler 14.5.1 are now the default for the container build. But the menu behind &quot;D&quot; can be still used to switch the major version. All the changes always run thru an automat ...
 ]]>
</description>
<link>https://blog.nashcom.de/nashcomblog.nsf/dx/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm</link>
<category>Domino</category>
<dc:creator>Daniel Nashed</dc:creator>
<comments>https://blog.nashcom.de/nashcomblog.nsf/dx/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm?opendocument&amp;comments</comments>
<guid isPermaLink="true">https://blog.nashcom.de/nashcomblog.nsf/dx/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm</guid>
<content:encoded><![CDATA[ <span style=" font-size:10pt;font-family:sans-serif"><br /> Domino &amp; Traveler 14.5.1 are now the default for the container build. But the menu behind &quot;<strong>D</strong>&quot; can be still used to switch the major version.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> All the changes always run thru an automation test. But you never know what might break.<br /> In this case it was a Traveler tar with a different name. Because it is compressed it needs the tar.gz extension.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> <br /> Took me a moment to find it today. But I wrote a work-around and the file name will be updated soon.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> Updating Domino servers to 14.5.1 is just a container build away -- if you run containers.<br /> I have updated my production servers and a couple of lab servers.<br /> <br /> But an update isn't as complicated as it was in earlier days also on other platforms.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> There is no big version change from 14.5 to 14.5.1 for Java versions and Libs.<br /> Everything would be expected to work unchanged and there are enhancements I am waiting for.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><strong><br /> <br /> ClamAV </strong><br /> <br /> <br /> One addition in Domino 14.5.1 is the mail flow scan with ClamAV instead of ICAP.<br /> This brings free anti-virus to any Domino environment and is something you might want to look into for server to server scans.</span><span style=" font-size:12pt"> </span><span style=" font-size:10pt;font-family:sans-serif"><br /> The scan is intelligent and works with a trusted JWT among servers which contain the scanner type and pattern along with an attachment hash. Actually hash of hashes, which avoids re-scan of the whole message inside a domain.</span><span style=" font-size:12pt"> <br /> <br /> </span><img  alt="Image:Domino/Traveler 14.5.1 shipped today - the container image is updated - ClamAV is added to Domino" border="0" src="https://blog.nashcom.de/nashcomblog.nsf/dx/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm/content/M2?OpenElement" />  ]]></content:encoded>
<wfw:commentRss> https://blog.nashcom.de/nashcomblog.nsf/dxcomments/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm</wfw:commentRss>
<wfw:comment> https://blog.nashcom.de/nashcomblog.nsf/dx/dominotraveler-14.5.1-shipped-today-the-container-image-is-updated-clamav-is-added-to-domino.htm?opendocument&amp;comments</wfw:comment>
</item>
</channel></rss>
